25 Sep
|
David Jones
|
Victoria
25 Sep
David Jones
Victoria
Job Description
Protect what matters. Strengthen cyber resilience. Help shape a security-conscious culture.
n
At David Jones, we are committed to creating secure, seamless and trusted experiences for our customers and our people. We are looking for a Cyber Security & GRC Analyst who can combine hands-on security operations with practical governance, risk and compliance expertise.
n
This is a broad and highly team-oriented role where you will monitor and respond to security events, coordinate vulnerability remediation, strengthen our cyber control environment and help embed secure behaviours across the organisation.
n
Working across Technology and the broader business, you will translate technical security information into clear, risk-based actions that protect our operations while enabling innovation and progress.
n
What will your day look like?
n
In this role, you will:
n
n
- Monitor and triage security alerts, events and reported concerns, escalating and coordinating responses in line with established processes
n
- Support the investigation of security incidents, including evidence gathering, root-cause analysis and identification of recurring issues
n
- Coordinate vulnerability scanning and work with system owners to prioritise remediation, patching and risk treatment
n
- Track vulnerabilities, control gaps and remediation actions through to closure
n
- Support identity and access management activities, including access reviews, privileged access checks and least-privilege assurance
n
- Maintain cyber security policies, standards, procedures and the security control framework
n
- Support cyber and technology risk assessments, control assurance activities and continuous control monitoring
n
- Coordinate evidence and stakeholder responses for internal and external audits
n
- Help maintain alignment with frameworks and obligations including the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS
n
- Coordinate cyber security awareness campaigns, training and phishing simulations
n
- Prepare operational and GRC reporting across incidents, vulnerabilities, risks, controls, audits and awareness measures
n
- Provide clear, practical security advice to Technology teams, project teams and stakeholders across the business
n
- Identify opportunities to automate, simplify and strengthen security processes, controls and reporting
n
n
What will you need to thrive?
n
You will bring approximately three years of experience across cyber security operations, cyber GRC, technology risk, audit or a comparable role combining these disciplines.
n
You will also have:
n
n
- Hands-on experience in security alert triage, incident analysis, vulnerability management and remediation coordination
n
- Experience supporting cyber risk assessments, control assurance, policy maintenance, audits and remediation tracking
n
- Working knowledge of security frameworks and standards such as the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS
n
- Exposure to security technologies across identity, email, endpoint, cloud and vulnerability management
n
- Experience with Microsoft security solutions and tools such as Proofpoint, CrowdStrike, Cortex, Rapid7 or Tenable
n
- The ability to analyse security information, identify patterns and translate technical findings into practical business actions
n
- Strong stakeholder engagement, organisation and follow-through
n
- The ability to balance operational security priorities with scheduled governance and compliance activities
n
- Strong written communication skills, with the ability to develop concise policies, procedures, reports, training materials and management updates
n
- Experience delivering cyber awareness communications, training or phishing simulations
n
- A relevant qualification in cyber security, information technology, risk or a related discipline, or equivalent practical experience
n
n
Relevant industry certifications, or active progress toward certification, will be highly regarded.
n
Why join David Jones?
n
Our purpose is to inspire like no other, and our people bring this to life every day.
n
At David Jones, you will join a culture where people are encouraged to be customer obsessed, empowered, inclusive and innovative. You will have the opportunity to work across a complex and iconic retail organisation, partnering with diverse teams to improve cyber resilience and build greater security capability across the business.
n
This role offers the chance to broaden your exposure across both cyber security operations and GRC, contribute to meaningful security improvements and help shape a culture where protecting our customers, people and business is everyone's responsibility.
n
Ready to inspire like no other?
n
If you are curious, collaborative and motivated by turning cyber risk into practical action, we would love to hear from you.
n
Apply now and help us build secure, resilient and trusted experiences across David Jones.
n
David Jones is committed to creating an inclusive workplace where everyone feels respected, valued and empowered to thrive. We welcome applications from people of all backgrounds, experiences and perspectives.
n
Be careful - Don't provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .
📌 Cyber Security & GRC Analyst (Victoria)
🏢 David Jones
📍 Victoria